By the Cliont product team
Penetration testing lead intake for cybersecurity professionals

Know which penetration testing leads deserve a scoping call

Ask prospects what environment needs testing, whether they hold documented authorization, and how many systems are in scope — then require an authorization document before a scoping call ever gets booked.

Video greetingGuided intakeDocument uploadInstant lead scoring
Live previewQuestion 1 of 6
What type of environment needs testing?
Web application
Mobile application
Network infrastructure

The exact intake your penetration testing leads complete

This is the real 6-question guided intake for Penetration Testing — the same flow your customers finish before you ever pick up the phone.

Preview
Your video greeting plays here

What a qualified penetration testing lead should tell you

Authorized, simulated attacks against a defined set of systems, applications, or networks to surface exploitable weaknesses, scoped by asset type, count, and proof of ownership before any testing begins.

  • Environment Testing
  • Own Or Have Documented
  • Prompting This Testing
  • How Many Systems, Applications,
  • This Environment Ever Undergone
  • Testing Take Place

The questions your team needs answered

Every penetration testing intake asks these — and why each one matters.

QuestionWhy it matters
What type of environment needs testing?The environment type determines which specialists and test methodology to scope, since every listed option except a nonsensical case carries high qualification weight.
Do you own or have documented authorization to test these systems?Documented authorization scores 10 versus just 1 for a 'no' answer, because testing without proof of ownership is a legal risk your team can't take on.
What is prompting this testing need?The stated driver — compliance, incident, routine, launch, or partner request — shapes how urgently and how the scoping call should be framed.
Approximately how many systems, applications, or endpoints are in scope?The number of in-scope systems or endpoints signals the likely size and cost of the engagement before your team gets on a call.
Has this environment ever undergone a penetration test before?Knowing whether the environment has been tested before tells your team if they're starting a baseline assessment or building on prior findings.
When do you need testing to take place?Stated timeline separates leads ready to schedule immediately from those still just exploring providers.

How Cliont scores penetration testing leads

Every answer is weighted automatically — no manual review required.

Value signals

  • Web application
  • Mobile application
  • Network infrastructure
  • Cloud environment
  • Internal systems
  • Not sure

Urgency signals

  • Immediately

See the lead your team receives

Penetration Testing Lead

92/100
High Priority
Environment typeWeb application
Documented authorizationYes
DriverCompliance requirement
Scope size6 to 20 systems
Prior penetration testNo
TimelineImmediately
Delivered to: Email · CRM · Calendar

From first click to qualified lead

Follow prospects and clients through one smooth, guided flow.

They land & meet you

Your video greeting plays instantly — a real face instead of a blank form.

They explain the project

Smart questions adapt to their project and capture the full scope.

They share the details

The scope and any documents come attached, so you can scope before the first call.

You get a ready lead

Scored and qualified — waiting for you to win it.

Built for penetration testing workflows

Cliont capabilityPenetration Testing application
Conditional document uploadRequires proof of system ownership or a signed authorization letter before a lead is marked qualified, closing the risk exposed by a 'No' answer on the authorization question.
Weighted scoring engineApplies the catalog's 10-vs-1 weighting on documented authorization so an unauthorized request never outranks a properly cleared one, regardless of how valuable the target environment looks.
Answer-based routingDirects prospects describing scanning-only needs toward the Vulnerability Assessment intake instead, based on their stated environment and driver.
CRM handoff with structured fieldsPasses environment type, scope size, and stated timeline straight into CRM fields so scoping calls start with technical context already logged.

Common penetration testing lead scenarios

Compliance-driven web app test

A prospect needs a web application tested to satisfy an auditor, has documented authorization, and wants to start immediately — the intake flags this as a high-priority, ready-to-schedule engagement.

Unauthorized network test request

Someone asks for a network infrastructure test but can't confirm they own or have written permission for the systems, triggering the low 'no' weight on the authorization question and holding the lead until proof is provided.

Large-scope cloud engagement

A first-time client with 21+ endpoints across a cloud environment selects 'within three months,' giving your team a sizable but not urgent lead to plan resourcing around.

Exploratory prospect, no timeline

A visitor marks the environment as 'not sure' and says they're just exploring options, which the intake still scores as viable but routes for a clarifying conversation rather than an immediate scoping call.

Connect Cliont to your workflow

Send leads

HubSpot, HighLevel, Salesforce, JobNimbus

Book projects

Google Calendar, Outlook Calendar, Calendly

Notify your team

Email, SMS, Slack

Automate follow-up

Zapier, Webhooks, API

Simple, transparent pricing

Choose the plan that works for your business.

Most popular

Professional

Unlimited intake forms and leads for your growing business.

$397 / month
14-day free trial · Cancel anytime
  • Unlimited intake forms
  • Custom video greetings
  • AI-powered voice bot
  • English + Spanish support
  • Automatic lead scoring
  • Digital estimates & e-signatures
  • Photo, video & file upload
  • Advanced analytics dashboard
Try free for 14 days

Pay Per Lead

Only pay when you receive a qualified lead.

$47 / qualified lead
No setup fees · No monthly fees
  • Unlimited intake forms
  • Custom video greetings
  • AI-powered voice bot
  • English + Spanish support
  • Automatic lead scoring
  • Digital estimates & e-signatures
  • Photo, video & file upload
  • Charged only for submitted leads
Get started

Penetration Testing lead-intake FAQs

How does the intake stop us from scoping a test we're not legally cleared to run?

The authorization question carries the heaviest weight in the catalog — a documented 'yes' scores 10, while 'no' scores 1 — so unauthorized requests are flagged well before your team invests time in a scoping call.

What if a lead says they're not sure what type of environment needs testing?

'Not sure' is still counted as a viable environment response in the scoring, but it signals that the scoping call should start with clarifying the target systems rather than jumping straight to logistics.

How does this intake differ from your Vulnerability Assessment intake?

This flow is built around active, authorized exploitation of specific systems, so it asks for documented authorization and in-scope counts up front — leads that only want automated scanning are a better fit for the Vulnerability Assessment intake.

Does the intake help us estimate engagement size before the call?

Yes — the question on how many systems, applications, or endpoints are in scope gives your team a rough sense of engagement size before you ever open the CRM record.

Can the intake tell us if this is a repeat client or a first-time test?

The prior-testing question captures whether the environment has ever undergone a penetration test before, which helps your team decide whether the call is a baseline assessment or a retest against prior findings.

Why does the intake ask what's driving the request?

Knowing whether the need stems from a compliance deadline, a recent incident, a partner request, or a routine assessment lets your team frame the scoping call and prioritize accordingly, even though the driver itself isn't weighted for scoring.

Turn penetration testing visitors into qualified clients

Give every penetration testing visitor a guided intake instead of a dead contact form — and get a scored, qualified lead before you take the first call.